PT-2026-99496 · WordPress · Online Scheduling/Appointment Booking System – Bookly

CVE-2026-86841

·

Published

2026-09-27

·

Updated

2026-09-28

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Online Scheduling and Appointment Booking System WordPress plugin versions prior to 28.3
Description The plugin fails to prevent the deserialization of untrusted input and does not properly restrict a privileged maintenance feature to administrators. This allows users who have been explicitly assigned the booking-management capability to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets. Deserialization is the process of converting a stored data format back into an object that the programming language can use.
Recommendations Update the Online Scheduling and Appointment Booking System WordPress plugin to version 28.3 or later.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86841

Affected Products

Online Scheduling/Appointment Booking System – Bookly